AI Governance

EUAIACT
EU AI Act

Risk-based AI regulation addressing prohibited practices, high-risk systems, transparency and general-purpose AI obligations across the AI lifecycle.

ISO23894
ISO/IEC 23894:2023

AI-specific risk management — identification, assessment, treatment, monitoring and communication of risks arising from AI systems.

ISO42001
ISO/IEC 42001:2023

Artificial intelligence management systems — organizational accountability, AI policies, lifecycle governance, risk management and continuous improvement.

NISTAIRMF
NIST AI Risk Management Framework

The Govern, Map, Measure and Manage approach for identifying and controlling risks arising from AI systems.

NISTGENAI
NIST Generative AI Profile

Governance considerations for generative AI and foundation-model applications, including risks from model outputs, data, security and human interaction.

OECDAI
OECD AI Principles

Responsible AI development and deployment principles — human-centred values, transparency, robustness, accountability and sustainable innovation.

Business Continuity

ISO22301
ISO 22301:2019

Business-continuity management addressing organizational resilience, business-impact analysis, continuity strategy, response and recovery.

ISO27031
ISO/IEC 27031:2011

ICT readiness for business continuity — connecting IT infrastructure with organizational resilience.

Data Centre

ISO22237
ISO/IEC 22237 / EN 50600

Data-centre facilities and infrastructure standards addressing power, environmental control, telecommunications and security.

TIA942
TIA-942

Telecommunications infrastructure standard for data centres — site infrastructure, telecommunications, electrical and mechanical requirements.

UPTIMETIER
Uptime Institute Tier Standard

Data-centre resilience and topology concepts across Tier I through Tier IV, including redundancy and fault-tolerance considerations.

Delivery & Management

AGILE
Agile / Scrum

Iterative delivery practices — product backlogs, sprint-based development, stakeholder feedback and continuous product improvement.

DEVSECOPS
DevOps / DevSecOps

Integration of development, infrastructure, security and operations into a single delivery lifecycle.

MLOPS
MLOps

Operational lifecycle for machine-learning and AI systems spanning deployment, monitoring, governance and continuous improvement.

PMBOK
PMBOK / PMI

Project-management body of knowledge — scope, schedule, cost, quality, resources, communications, risk and stakeholder management.

Enterprise Risk

COSOERM
COSO Enterprise Risk Management

Enterprise-risk concepts connecting strategy, performance, governance, risk and organizational decision-making.

COSOIC
COSO Internal Control Framework

Internal-control concepts spanning control environment, risk assessment, control activities, information/communication and monitoring.

ISO31000
ISO 31000:2018

Risk-management principles for systematic identification, analysis, evaluation, treatment, monitoring and communication of enterprise risk.

3LINES
Three Lines Model

Governance model distinguishing responsibilities across operational management, risk/compliance oversight and independent assurance.

Governance

COBIT
COBIT

Technology-governance framework connecting enterprise objectives with IT governance, risk, controls, performance and value delivery.

ISO38500
ISO/IEC 38500:2024

Board and executive-level principles for effective governance and organizational use of information technology.

Privacy

BCPIPA
BC PIPA

British Columbia Personal Information Protection Act — provincial privacy requirements for private-sector organizations.

DPDP
Digital Personal Data Protection Act, 2023

India's data-protection law — data fiduciary responsibilities, consent, data-principal rights, security safeguards and breach obligations.

GDPR 2 clauses
GDPR (EU) 2016/679

General Data Protection Regulation

ISO27701 1 clause
ISO/IEC 27701:2019

Privacy Information Management System — extends ISO 27001 for PII processing.

ITACT
IT Act, 2000 (India)

Technology-law framework for electronic systems, cybersecurity, digital information and intermediary/technology operations in India.

PIPEDA
PIPEDA

Canadian federal privacy law governing the collection, use, disclosure and safeguarding of personal information.

Quality

ISO9001
ISO 9001:2015

Process-based quality-management concepts covering customer focus, leadership, process management and continual improvement.

Security

CIS
CIS Controls

Prioritized cybersecurity practices addressing assets, identities, vulnerabilities, access, monitoring and recovery.

ISO27001 4 clauses
ISO/IEC 27001:2022

Information security management system requirements and Annex A controls.

ISO27002
ISO/IEC 27002:2022

Information security control guidance spanning organizational, people, physical and technological security.

ISO27017
ISO/IEC 27017:2015

Cloud-specific information-security controls applicable to cloud service providers and customers.

ISO27018
ISO/IEC 27018:2019

Protection of personally identifiable information processed within public-cloud environments.

NISTCSF
NIST Cybersecurity Framework

Cybersecurity risk management across Govern, Identify, Protect, Detect, Respond and Recover.

NIST80053
NIST SP 800-53

Security and privacy control concepts applicable to enterprise and government information systems.

SOC12
SOC 1 / SOC 2

Assurance expectations and control environments, particularly SOC 2 Trust Services Criteria around security, availability, processing integrity, confidentiality and privacy.

Service Management

ISO20000
ISO/IEC 20000-1:2018

IT service management principles for planning, delivery, monitoring and continuous improvement of technology services.

ITIL
ITIL

Service-management concepts covering incident, problem, change, service-level, configuration, availability and capacity management.

Software & DevSecOps

NISTSSDF
NIST Secure Software Development Framework

Secure-development principles covering organizational preparation, software protection, secure production and vulnerability response.

OPENCHAIN
OpenChain / Open-Source Governance

Open-source software governance — component identification, licence obligations, approval processes and software supply-chain risk.

OWASP
OWASP

Application-security principles and common vulnerability frameworks relevant to web applications, APIs, authentication and data handling.